Vulnerability Name: | CVE-2019-5597 (CCN-161097) | ||||||||||||
Assigned: | 2019-05-14 | ||||||||||||
Published: | 2019-05-14 | ||||||||||||
Updated: | 2019-06-11 | ||||||||||||
Summary: | In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in the pf IPv6 fragment reassembly logic incorrectly uses the last extension header offset from the last received packet instead of the first packet allowing maliciously crafted IPv6 packets to cause a crash or potentially bypass the packet filter. | ||||||||||||
CVSS v3 Severity: | 9.1 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H) 7.9 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C)
7.9 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-5597 Source: MISC Type: Third Party Advisory, VDB Entry http://packetstormsecurity.com/files/152933/FreeBSD-Security-Advisory-FreeBSD-SA-19-05.pf.html Source: CCN Type: Oracle CPUJul2019 Oracle Critical Patch Update Advisory - July 2019 Source: BID Type: UNKNOWN 108395 Source: XF Type: UNKNOWN freebsd-cve20195597-dos(161097) Source: MISC Type: Patch, Vendor Advisory https://security.FreeBSD.org/advisories/FreeBSD-SA-19:05.pf.asc Source: CONFIRM Type: UNKNOWN https://security.netapp.com/advisory/ntap-20190611-0001/ Source: CCN Type: FreeBSD Security Advisory FreeBSD-SA-19:05.pf IPv6 fragment reassembly panic in pf(4) Source: MISC Type: UNKNOWN https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html Source: MISC Type: Exploit, Third Party Advisory https://www.synacktiv.com/ressources/Synacktiv_OpenBSD_PacketFilter_CVE-2019-5597_ipv6_frag.pdf Source: CCN Type: WhiteSource Vulnerability Database CVE-2019-5597 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |